FortiSwitch Secure Access — FortiLink, NAC & PoE Switching

  • Home
  • FortiSwitch Secure Access — FortiLink, NAC & PoE Switching

Fortinet · FortiSwitch

FortiSwitchEthernet switching that the firewall can actually see

FortiLink integration enables unified management of security and switching

FortiSwitch secure access Ethernet switching integrated with FortiGate via FortiLink
FortiSwitch

FortiSwitch Secure Access Series

Enterprise-grade secure Ethernet switching for small businesses and branch offices

FortiSwitch Overview

The FortiSwitch Access Family is tailored to meet the unique demands of enterprise branch offices and small businesses. An unparalleled combination of security, ease of use, and scalability makes FortiSwitch the ideal choice for Ethernet infrastructure. Managing a remote enterprise branch or small business network can be challenging due to limited visibility of connected devices, time constraints for LAN management, and a shortage of skilled personnel. The FortiSwitch Secure Access family seamlessly integrates Ethernet networking with advanced security features, effectively eliminating the silos that hinder day-to-day management.

Key Benefits:

  • Standalone or integrated FortiLink deployment with FortiGate
  • Zero-touch deployment for quick and simple setup
  • On-premise and cloud-based management options
  • Easy-to-use network access control (NAC) at no additional cost
  • User- and device-based access control and policy enforcement
  • Secure access service edge (SASE) support
  • Power over Ethernet (PoE/PoE+) support
  • Wire-speed switching with up to 10GE uplinks

Key Features

Security Integration

  • FortiLink integration with FortiGate
  • Network Access Control (NAC)
  • Built-in Ethernet port security
  • Authentication (802.1X, MAC-based, MAB)
  • DHCP snooping and ARP inspection
  • Device detection and profiling
  • IoT identification via FortiGuard

Management Features

  • Auto discovery of multiple switches
  • Centralized VLAN configuration
  • Dynamic port profiles
  • FortiLink stacking
  • Health monitoring
  • Intuitive web interface
  • REST API for automation

Network Capabilities

  • Layer 2 and Layer 3 switching
  • Link aggregation with LACP
  • Spanning Tree (MSTP, RSTP)
  • VLAN tagging and mapping
  • IGMP and MLD snooping
  • QoS and traffic prioritization
  • PoE/PoE+ management

Secure Networking Through FortiLink

FortiLink is an innovative proprietary management protocol that enables seamless integration between a FortiGate Next-Generation Firewall and the FortiSwitch Ethernet switching platform. By using FortiLink, the FortiSwitch becomes a logical extension of the FortiGate, allowing for centralized management of both network security and access layer functions through a single interface.

FortiLink Benefits:

  • Simplified management of switches through the FortiGate interface
  • Centralized security policy configuration and enforcement
  • Automatic discovery and authorization of FortiSwitch devices
  • Unified visibility of network security and access layer
  • Easy configuration of VLANs and port settings
  • Seamless integration with FortiAP for complete branch solution

FortiLink integration enables unified management of security and switching

Easy-to-use Network Access Control (NAC)

FortiLink integration enables basic NAC functionality to profile and securely onboard devices as they connect. FortiLink NAC offers visibility into all connected devices, automated segmentation and security policies for IoT devices, quarantine capabilities if compromised, and virtual patching to help protect against threats.

Device Visibility

Gain complete visibility into all devices connected to your network, including IoT devices, with automatic identification and categorization.

Automated Segmentation

Automatically place devices in appropriate network segments based on device type, user role, or security posture.

Security Policies

Apply granular security policies at the port level to ensure only authorized devices gain network access.

Quarantine Options

Automatically quarantine compromised devices to prevent threats from spreading across your network.

FortiSwitch Product Series

100F Series

Entry-Level The FortiSwitch 100F series provides secure, feature-rich Ethernet connectivity for small businesses and branch offices. Available in 8, 24, and 48-port configurations with optional PoE/PoE+ support.

Available Models:

  • FS-108F (8 port)
  • FS-108F-POE (8 port PoE)
  • FS-108F-FPOE (8 port full PoE)
  • FS-124F (24 port)
  • FS-124F-POE (24 port PoE)
  • FS-124F-FPOE (24 port full PoE)
  • FS-148F (48 port)
  • FS-148F-POE (48 port PoE)
  • FS-148F-FPOE (48 port full PoE)

Key Specifications:

  • GE RJ45 ports with GE/10GE SFP/SFP+ uplinks
  • PoE budgets up to 740W (FPOE models)
  • Switching capacity up to 176 Gbps
  • Desktop or 1RU rackmount form factors
  • Fanless options available
  • MAC address storage up to 32K

Ideal For:

  • Small offices and retail locations
  • Branch offices
  • IP telephony deployments
  • Wireless access point connectivity
  • Secure wired access

100G Series

Next-Gen The FortiSwitch 100G series offers multi-gigabit capabilities with 2.5G/1G ports, providing higher performance for bandwidth-intensive applications while maintaining the security and ease of use of the FortiSwitch platform.

Available Models:

  • FS-110G-FPOE
  • FS-124G
  • FS-124G-FPOE

Key Specifications:

  • 2.5G/1G multi-gigabit RJ45 ports
  • 10G SFP+ uplinks
  • PoE/PoE+ with budgets up to 780W
  • Switching capacity up to 240 Gbps
  • Performance up to 355 Mpps
  • MAC address storage up to 32K

Ideal For:

  • High-performance workstations
  • Wi-Fi 6/6E access point connectivity
  • Video surveillance systems
  • Bandwidth-intensive applications
  • Growing business networks

200 Series

Business-Class The FortiSwitch 200 series provides business-class switching with advanced features, including optional Layer 3 capabilities, redundant power supply options, and support for larger deployments.

Available Models:

  • FS-224D-FPOE
  • FS-224E
  • FS-224E-POE
  • FS-248D
  • FS-248E-POE
  • FS-248E-FPOE

Key Specifications:

  • 24 or 48 GE RJ45 ports with GE/10GE uplinks
  • Optional PoE/PoE+ with budgets up to 740W
  • Switching capacity up to 104 Gbps
  • Optional redundant power supply support
  • Advanced Layer 3 capabilities
  • Dedicated management port

Ideal For:

  • Medium-sized business networks
  • Campus edge deployments
  • Branch office connectivity
  • Mission-critical applications
  • Advanced routing needs

Deployment Options

FortiLink Mode

Connect your FortiSwitch to a FortiGate firewall to enable seamless integration with the Fortinet Security Fabric. In FortiLink mode, the FortiGate manages the FortiSwitch as an extension of the firewall, providing unified security policy management and visibility.

Benefits:

  • Centralized management through FortiGate interface
  • Security policy enforcement at the switch port
  • Integration with FortiGate’s NAC capabilities
  • User identity awareness and policy enforcement
  • Advanced security features like virtual patching

Standalone Mode

Deploy FortiSwitch as a standalone device, managed through its own web interface or FortiEdge Cloud. This option is ideal for environments without a FortiGate or for networks that require independent switch management.

Benefits:

  • Flexible deployment without requiring a FortiGate
  • Complete control over switch configuration
  • Cloud management options through FortiEdge Cloud
  • Full access to switch features and capabilities
  • Simple migration path to FortiLink in the future

Integration with the Fortinet Security Fabric

FortiSwitch is a key component of the Fortinet Security Fabric, providing secure access at the network edge and extending security policies to the access layer. When deployed with other Fortinet products, FortiSwitch enables a comprehensive security solution with unified management and visibility.

FortiGate Integration

FortiSwitch integrates with FortiGate firewalls through FortiLink, enabling centralized management and security policy enforcement across the network.

FortiAP Integration

Power and manage FortiAP wireless access points through FortiSwitch, creating a unified wired and wireless network with consistent security policies.

FortiManager Integration

Centrally manage multiple FortiSwitch deployments through FortiManager, providing scalability and consistency across distributed environments.

FortiAnalyzer Integration

Collect and analyze logs from FortiSwitch devices to gain insights into network activity and security events across the entire network.

Common Use Cases

Secure Branch Connectivity

Deploy FortiSwitch in branch offices to provide secure, reliable connectivity with centralized management from headquarters. FortiLink integration with FortiGate enables consistent security policies across all locations.

Recommended Models:

FS-124F, FS-124F-POE, FS-124G

Key Benefits:

  • Zero-touch deployment
  • Centralized management
  • Consistent security policies
  • Secure VPN connectivity

Small Business Network

Create a secure, reliable network for small businesses with integrated security and easy management. FortiSwitch provides the performance and features needed without complexity.

Recommended Models:

FS-108F, FS-108F-POE, FS-110G-FPOE

Key Benefits:

  • Simplified management
  • Integrated security
  • PoE for phones and APs
  • Scalable as business grows

Campus Edge Network

Deploy FortiSwitch at the edge of campus networks to provide secure access for users and devices. Integration with NAC ensures only authorized devices connect to the network.

Recommended Models:

FS-148F, FS-224E-POE, FS-248E-FPOE

Key Benefits:

  • User and device authentication
  • Network segmentation
  • High port density
  • Advanced security features

IoT Device Security

Secure IoT devices by connecting them to FortiSwitch with NAC policies. Automatically identify and segment IoT devices to minimize security risks.

Recommended Models:

FS-124F-FPOE, FS-124G-FPOE

Key Benefits:

  • IoT device detection
  • Automatic segmentation
  • PoE for powered devices
  • Security policy enforcement

Ready to Secure Your Network with FortiSwitch?

Contact our team to learn more about FortiSwitch solutions and find the perfect model for your organization.

Frequently Asked Questions

What is FortiLink and how does it work?

FortiLink is a proprietary management protocol developed by Fortinet that allows a FortiGate firewall to manage FortiSwitch devices. When FortiLink is configured, the FortiSwitch becomes a logical extension of the FortiGate, allowing administrators to manage both security and switching from a single interface. FortiLink enables features like centralized VLAN configuration, security policy enforcement at the port level, and advanced NAC capabilities.

Can FortiSwitch be managed without a FortiGate?

Yes, FortiSwitch can be deployed in standalone mode without requiring a FortiGate. In standalone mode, you can manage the switch through its web interface or FortiEdge Cloud. However, some advanced security features and integrations with the Fortinet Security Fabric require FortiLink mode with a FortiGate.

What is the difference between POE and FPOE models?

POE models provide Power over Ethernet on a limited number of ports (typically half of the available ports), while FPOE (Full POE) models provide Power over Ethernet capabilities on all ports. FPOE models also generally have higher power budgets to support more PoE devices simultaneously.

Does FortiSwitch include Network Access Control (NAC)?

Yes, FortiSwitch includes basic NAC functionality at no additional cost when deployed in FortiLink mode with a FortiGate. This includes device identification, automatic segmentation, and security policy enforcement. For more advanced NAC capabilities, FortiSwitch integrates with FortiNAC (sold separately).

What warranty comes with FortiSwitch products?

FortiSwitch products include a limited lifetime warranty that covers hardware failures under normal use. This warranty provides peace of mind for your investment in network infrastructure. For detailed terms and conditions, please refer to the Fortinet Warranty Policy.

Delivered by P J Networks

Supplied, deployed and then actually run

We are not a fulfilment desk. Everything here is sized against your estate, deployed to a plan with a rollback, and monitored afterwards from our own ISO/IEC 27001:2022 certified NOC and SOC in Mayapuri, New Delhi — by engineers who already know your environment. Since 2002.

Sized on real numbers

Specified from your traffic, workload and growth — not a datasheet maximum.

Migration planned first

Cutover and rollback written before anything is ordered, around your change window.

24×7 operation

Monitored from our NOC and SOC, with named escalation.

Audit-ready

ISO/IEC 27001:2022 certified with the SOC in scope; logging and retention aligned to CERT-In, RBI, SEBI and DPDP.

P J Networks 24x7 network and security operations centre in Delhi
Our NOC & SOC, Delhi
3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

Questions we get asked

FortiSwitch, answered

What does FortiLink actually change?

It makes the switch a logical extension of the FortiGate, so you manage ports, VLANs and access policy from the firewall interface instead of a second console. In practice that removes the gap where access-layer events are invisible to the security team — and it means one policy set rather than two that drift apart.

Is network access control really included at no extra cost?

Yes. Basic NAC comes with the FortiLink integration rather than as a separate licensed product, which is unusual at this price point. It covers device detection and profiling, dynamic port assignment and quarantine of unknown devices.

Can FortiSwitch run without a FortiGate?

It can run standalone with its own management, but you lose the main reason to choose it. If you are not going to pair it with a FortiGate, we would usually point you at Cisco instead and say so honestly.

Next step

Talk to an engineer, not a salesperson

Tell us what you are running and what problem you are trying to solve. We will tell you what you need, what you do not, and what it costs to run.

P J Networks Pvt Ltd · C-160, Mayapuri Phase II, New Delhi 110064
+91 98183 61787 · sanjay@pjnetworks.com